October 12, 2021
Los Angeles, California + Virtual
View More Details & Registration

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for KubeCon + CloudNativeCon North America 2021 - Los Angeles, CA + Virtual and add this Co-Located event to your registration to participate in these sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.

Please note: This schedule is automatically displayed in Pacific Standard Time (PST), UTC -7. To see the schedule in your preferred timezone, please select from the drop-down menu to the right, above "Filter by Date." The schedule is subject to change.

IMPORTANT NOTE: Timing of sessions and room locations are subject to change through Monday, September 13 due to schedule changes that will be made as speakers finalize whether speaking in person or virtually.
How to Implement Advanced Deployments [clear filter]
Tuesday, October 12

2:25pm PDT

GitOps in the Real World: Opportunities for Developer Experience Improvement - Christopher Lane & Alex Crane, Chick-fil-A
GitOps is a pattern for managing the state of Kubernetes clusters using git as the source of truth. The entire state of the cluster is declared in manifests stored in git repositories and any changes to the manifests follow well-known git processes. Once the manifests are version controlled in git, then there's a number of state reconcilers (Flux, ArgoCD and the like) that can automatically apply changes from the repository. However, this leaves a significant gap in the process: How do we build and get the manifests *into the git repositories* in the first place? This talk will walk through Chick-fil-A's experiences with GitOps to manage the state of our production clusters at scale and offer what we see as opportunities to improve the frontend of the process.

avatar for Christopher Lane

Christopher Lane

Enterprise Architect, Chick-fil-A
Christopher Lane is a Principal Enterprise Architect with Chick-fil-A focused on Customer Technology Solutions (CTS). CTS' profile includes all customer-facing applications and services at Chick-fil-A, including our industry-leading Chick-fil-A One mobile application. Prior to joining... Read More →

Alex Crane

Enterprise Architect, Chick-fil-A

Tuesday October 12, 2021 2:25pm - 2:55pm PDT
Petree Hall C + Online Los Angeles Convention Center - 1201 S. Figueroa Street, Los Angeles, CA 90015

4:20pm PDT

Building Flux's Multi-Tenant API with K8s User Impersonation - Leigh Capili, VMware
Kubernetes is hard to operate in a multi-tenant manner. As organizations add API's and privileged controllers to their clusters, it becomes infeasible to build clusters that teams can share with each other safely. This is a design issue with the way projects extend Kubernetes.  While policy engines like Gatekeeper and Kyverno enable cluster owners to patch over insecure API surfaces to protect tenants, there are patterns that produce API's resistant to cross-tenant issues. It's possible to extend Kubernetes without relying on admission-based policy engines to restrict API boundaries and controller implementations.  This session will teach you how to enable multiple organizations and teams to work safely together across namespaces and clusters. Flux will be used as an example on how to use RBAC, impersonation and kubeConfig secrets, but the techniques shown can be used to improve projects across the ecosystem!

avatar for Leigh Capili

Leigh Capili

Staff Developer Advocate, VMware
Leigh is an empathetic speaker and developer with niches in cloud-native systems and security. He has a background in building software to manage infrastructure. Leigh contributes to Kubernetes and Flux and is frequently working on his next software demo. He also co-maintains Ignite... Read More →

Tuesday October 12, 2021 4:20pm - 4:50pm PDT
Petree Hall C + Online Los Angeles Convention Center - 1201 S. Figueroa Street, Los Angeles, CA 90015
  • Timezone
  • Filter By Venue Los Angeles, California, USA
  • Filter By Type
  • Convincing Larger Organizations to Adopt GitOps
  • End User Talks Around GitOps Implementations
  • How to Implement Advanced Deployments
  • Keynote
  • Lightning Talk
  • Networking + Break
  • Use of Open Source Tooling to Achieve GitOps
  • War stories of how GitOps helped and Where Systems Broke Down
  • Talk Type

Filter sessions
Apply filters to sessions.